Quick answer · the 30-second read
Yes. US healthcare organisations can use electronic signatures on patient consent forms, authorisations and contracts. HIPAA, the main US health privacy law, does not set its own rules for electronic signatures. An e-signature is compliant if two things are true. The signature must be legally valid under general US e-signature law, meaning the ESIGN Act or the state’s version of UETA. And any patient information in the signed document must be protected under HIPAA’s privacy and security rules. A new federal rule, finalised in March 2026, adds the first specific HIPAA e-signature standard, but it applies only to paperwork supporting insurance claims.
Key facts
|
Does HIPAA itself say anything about electronic signatures?
Almost nothing, which is where the confusion comes from. When HIPAA was passed in 1996, section 1173 told the health department to adopt standards for authenticating signatures in certain healthcare transactions. A digital signature standard was proposed in the 1998 draft of the Security Rule. It was dropped from the final rule in 2003, on the basis that the technology was not mature enough and the industry was not ready.
The United States Department of Health and Human Services (HHS) guidance since then has been clear on two points. First, the Security Rule does not require the use of electronic or digital signatures. Second, no standards exist under HIPAA for electronic signatures, so covered entities must make sure any signature they use creates a legally binding contract under the state or other law that applies.
What makes an electronic signature HIPAA-compliant in practice?
Two things together. First, the signature must be legally valid. In the US that means it must satisfy the ESIGN Act (15 U.S.C. § 7001), the state’s version of UETA, and any state law on medical consent.
Second, the organisation must protect any patient information in the signed document. Identifiable patient data is known in the law as protected health information, or PHI. HIPAA’s Security Rule sets out how it must be looked after, and the most relevant requirements are the technical safeguards at 45 CFR 164.312. In practice they mean four things. Check who is signing. Keep a record of who signed what and when. Encrypt documents while they are being sent and stored. Store them so any tampering would show.
The signing platform is also important. If an e-signature provider handles patient information for a healthcare organisation, the law treats the provider as a business associate. That means the organisation must have a signed contract with the provider, called a business associate agreement, before any patient documents go through it. HHS has confirmed that this agreement can itself be signed electronically.
Which healthcare documents can be signed electronically?
Most of the documents a patient or partner organisation ever signs. Authorisations to use or share patient information must be in writing, but the writing can be electronic (45 CFR 164.508). The same goes for confirmations that a patient received the privacy notice, treatment consent forms, telehealth intake forms and business associate agreements. The test in every case is the same. The signature must be legally valid, and any patient information involved must be protected.
What changed in 2026?
In March 2026, HHS and Centers for Medicare & Medicaid Services (CMS) finalised a rule that creates the first specific HIPAA electronic signature standard. It is known as CMS-0053-F and was published in the Federal Register on 24 March 2026. The rule took effect on 26 May 2026, and organisations must comply by 26 May 2028.
It applies only to claims attachments. These are the supporting documents that healthcare providers and insurers exchange when handling a claim, such as medical records, imaging, clinical notes and lab results. The rule adopts an HL7 standard for digital signatures used with those transactions. CMS projects it will save around $781 million a year by replacing fax and post.
Two limits are worth noting. The rule does not change anything for patient-facing documents such as consent forms and authorisations, which remain governed by general e-signature law. And the proposed version of the rule would also have covered prior authorisation transactions, but the final rule dropped those and covers claims attachments only.
Which rules apply beyond HIPAA?
HIPAA is not the only law that touches signatures in US healthcare. Electronic prescriptions for controlled drugs have their own, stricter federal rules (21 CFR Part 1311), including identity checks and two-factor signing. Records in clinical trials regulated by the FDA fall under 21 CFR Part 11. State law adds its own layer, because rules on consent and medical records vary from state to state. This page covers US law only.
Note: UK health records are governed by UK GDPR and the duty of confidentiality, not HIPAA.
Sources
- HHS, FAQ: Does the Security Rule require the use of an electronic or digital signature?
- HHS, The Security Rule (45 CFR Part 160 and Part 164, Subparts A and C)
- 45 CFR 164.312, technical safeguards
- 45 CFR 164.508, uses and disclosures for which an authorisation is required
- HHS/CMS final rule on healthcare claims attachments and electronic signatures, published 24 March 2026
- HIPAA Journal, Can E-Signatures Be Used Under HIPAA Rules?
- ESIGN Act, 15 U.S.C. § 7001